Why has identity become the new security perimeter?

In 2023, a cyber attacker called an IT help desk of a large hospitality and casino operator, posing as an employee. A ten-minute call was enough to reset a password and gain administrator access to the identity system. What followed was a 10-day shutdown of slot machines, digital keys, and booking systems, with losses estimated at over $100 million. A rival company, hit by the same attacker weeks earlier, paid a reported $15 million ransom instead.

In both cases, the person within the company’s ecosystem believed the call to be a genuine one and mistook the fake identity as a real one. The infiltrator didn’t come through the firewall. It is for this reason, identity not the network, has become the perimeter that matters most when we deal with cybersecurity.

The network perimeter has dissolved

For decades, security meant protecting the network: firewalls, VPNs, and a fixed set of office devices etc. Cloud, remote work, SaaS, and now AI agents have worn that boundary away. According to Verizon Business' 2025 Data Breach Investigations Report, which analysed 22,000+ security incidents worldwide (including 12,195 confirmed breaches), stolen logins were the single biggest way attackers got in, appearing in nearly 9 in 10 basic web attacks.  Ransomware featured in 44% of breaches, and over half of those victims already had credentials circulating on the dark web beforehand. Attackers increasingly don't break in, they log in.

Machine identities make this worse. API keys, service accounts, bots and AI agents now outnumber human identities inside the average company by roughly 82 to 1, and nearly half carry access to sensitive systems mostly untracked, rarely reviewed.[1]

AI: both weapon and shield

This is one of four priorities we have flagged for Boards in 2026, alongside regulatory change, quantum risk, and resilience. AI helps security teams detect threats faster but also helps attackers scale and personalise social engineering the exact playbook used in the casino operator breach mentioned above. As Jan Matto, Group Head of Cyber Security, Forvis Mazars puts it, the future of cyber security isn’t about choosing between security and innovation it’s about achieving both at once.

The risk boards often underestimate is “shadow AI” employees quietly using unapproved AI tools with company data.

Our recommended action: A formal AI governance framework, with teams required to report how they use AI.

The Indian picture: fast growth, rising cost

India's identity security market is expanding at a mid-teens compound rate through the early 2030s among the fastest in Asia-Pacific.

According to the latest IBM study, the average data breach in India now costs USD 2.68 million, up from USD 2.31 million a year earlier a record. Financial services, technology and communications were hit hardest, averaging USD 4.3 million, USD 3.75 million crore and USD 3.63 million per breach. Automation made a real difference: firms with little or no automation took 236 days to identify a breach and paid USD 3.32 million on average, versus 175 days and USD 2.24 million for those with extensive automation yet only 32% had reached that maturity.[2]

A large Indian health insurer illustrates how this plays out. In 2024, records of roughly 31 million policyholders were exposed after attackers used old, leaked login credentials combined with a design flaw letting one valid session pull far more data than it should no firewall involved, just a real-looking identity doing things it shouldn’t. With India’s data protection law and sector regulators now enforcing access-control rules, such gaps are only getting costlier.[3]

What business leaders are telling us?

Our C-suite barometer, surveying 1,700+ executives across 35+ countries, shows how seriously this is landing in boardrooms especially in technology, media and telecommunications (TMT). Transforming IT is the top strategic priority for 60% of TMT executives, up from 43% a year earlier, and most are already deploying generative AI (78%), it said. Yet the same executives cite security protocols and regulatory compliance among their biggest barriers.

The gap is telling: 44% say they are only partially prepared for tightening legislation such as Network and Information Security 2 (NIS2) and Digital Operational Resilience Act (DORA), and just 1 in 5 spend over 20% of IT budget on cybersecurity. Two-thirds believe their data is “completely” protected yet most still name improving data quality as a top priority. [5]

What this means for the leadership?

  • Trust must be continuous, not a one-time check. A single trusted login can do enormous damage if that trust was misplaced.
  • Governance must cover machines and AI, not just people. API keys, service accounts and AI tools need the same discipline as an employee's access card issued carefully, reviewed regularly, switched off when unneeded.
  • This is a boardroom issue, not an IT one. A 10-day shutdown, a USD 2.68 million average breach cost, a third-lower price tag for firms with mature automation these are business numbers, and identity security now sits in board papers alongside customer trust and continuity.

The bottom line

Identity risk is undergoing a fundamental transformation, evolving from the protection of human identities to the governance of machine identities and, increasingly, autonomous AI agents.

The first phase was dominated by human identity compromise, where attackers impersonated legitimate users to gain unauthorized access. The second emerged with the exponential growth of machine identities- service accounts, APIs, applications, workloads, and other non-human entities creating an expanding and increasingly complex access landscape.

In July 2026, OpenAI revealed a third stage: AI models autonomously used stolen credentials to access Hugging Face's production systems without any human instruction. Autonomous AI systems have the potential to use existing credentials and permissions to make decisions and execute actions with limited or no direct human intervention. This fundamentally changes the nature of the risk. The challenge is no longer simply preventing unauthorised access; it is ensuring that every authorised identity human, machine, or AI uses its access appropriately, within the intended context and with the right level of control.

This makes identity far more than an IT security function. Identity is becoming the foundation of digital trust and a critical component of enterprise risk management.

Organisations that can continuously authenticate, authorise, monitor, and govern identities in real time will be better positioned to reduce cyber risk, strengthen resilience, meet regulatory expectations, and protect critical business assets.


 

[1] https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf

[2] https://www.fortuneindia.com/amp/story/technology/indias-average-data-breach-cost-hits-record-255-crore-in-2026-as-ai-powered-attacks-rise-ibm/151591

[3] https://www.reuters.com/technology/cybersecurity/hacker-uses-telegram-chatbots-leak-data-top-indian-insurer-star-health-2024-09-20/

Want to know more?